快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 353571
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-13300 |
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
|
MEDIUM | 6.9 | 2025-11-17 |
itsourcecode Web-Based Internet Laboratory Management System
itsourcecode web-based_internet_laboratory_management_system
|
CVE NVD | |
| CVE-2025-36299 |
IBM Planning Analytics Information Disclosure
|
MEDIUM | 4.3 | 2025-11-17 |
IBM IBM Planning Analytics Local
ibm planning_analytics_local
+1个
|
CVE NVD | |
| CVE-2025-13299 |
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
|
MEDIUM | 6.9 | 2025-11-17 |
itsourcecode Web-Based Internet Laboratory Management System
itsourcecode web-based_internet_laboratory_management_system
|
CVE NVD | |
| CVE-2025-13298 |
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
|
MEDIUM | 6.9 | 2025-11-17 |
itsourcecode Web-Based Internet Laboratory Management System
itsourcecode web-based_internet_laboratory_management_system
|
CVE NVD | |
| CVE-2025-13297 |
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
|
MEDIUM | 6.9 | 2025-11-17 |
itsourcecode Web-Based Internet Laboratory Management System
itsourcecode web-based_internet_laboratory_management_system
|
CVE NVD | |
| CVE-2025-34323 |
Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules
|
HIGH | 8.5 | 2025-11-17 |
Nagios Log Server
nagios log_server
+1个
|
CVE NVD | |
| CVE-2025-34322 |
Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries
|
HIGH | 8.6 | 2025-11-17 |
Nagios Log Server
nagios log_server
+1个
|
CVE NVD | |
| CVE-2025-55059 |
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
|
MEDIUM | 4.8 | 2025-11-17 |
Rumpus FTP Server
maxum rumpus
|
CVE NVD | |
| CVE-2025-55058 |
CWE-20 Improper Input Validation
|
MEDIUM | 4.5 | 2025-11-17 |
Rumpus FTP Server
maxum rumpus
|
CVE NVD | |
| CVE-2025-55057 |
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
|
MEDIUM | 4.5 | 2025-11-17 |
Rumpus FTP Server
maxum rumpus
|
CVE NVD | |
| CVE-2025-64756 |
glob CLI: Command injection via -c/--cmd executes matches with shell:true
|
HIGH | 7.5 | 2025-11-17 |
isaacs node-glob
isaacs node-glob
+1个
|
CVE NVD | |
| CVE-2025-55056 |
Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scri...
|
MEDIUM | 4.8 | 2025-11-17 |
Rumpus FTP Server
maxum rumpus
|
CVE NVD | |
| CVE-2025-55055 |
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
|
MEDIUM | 6.8 | 2025-11-17 |
Rumpus FTP Server
maxum rumpus
|
CVE NVD | |
| CVE-2025-64758 |
@dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message
|
MEDIUM | 4.8 | 2025-11-17 |
DependencyTrack frontend
|
CVE NVD | |
| CVE-2025-64342 |
ESF-IDF's ESP32 Bluetooth Controller Has an Invalid Access Address Vulnerability
|
MEDIUM | 6.9 | 2025-11-17 |
espressif esp-idf
espressif esp-idf
+3个
|
CVE NVD | |
| CVE-2025-58407 |
GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSet
|
HIGH | 7.4 | 2025-11-17 |
Imagination Technologies Graphics DDK
imaginationtech ddk
|
CVE NVD | |
| CVE-2025-13193 |
Libvirt: information disclosure via world-readable vm snapshots
|
MEDIUM | 5.5 | 2025-11-17 |
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 6
+3个
|
CVE NVD | |
| CVE-2025-13291 |
Campcodes Supplier Management System confirm_order.php sql injection
|
MEDIUM | 6.9 | 2025-11-17 |
Campcodes Supplier Management System
campcodes supplier_management_system
|
CVE NVD | |
| CVE-2025-58410 |
GPU DDK - Multiple calls into PhysmemGEMPrimeExport can inherit write access permission for an existing read-only dma_buf import PMR
|
HIGH | 7.5 | 2025-11-17 |
Imagination Technologies Graphics DDK
imaginationtech ddk
+5个
|
CVE NVD | |
| CVE-2025-62519 |
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
|
HIGH | 7.2 | 2025-11-17 |
thorsten phpMyFAQ
phpmyfaq phpmyfaq
|
CVE NVD |